Disclosed is an operation method for a dynamic analyzer for analyzing an execution state of a web application. The present invention comprises the steps of: analyzing an execution state of the web application on the basis of a final attack string including a parameter which indicates a particular operation to be executed through the web application; and performing an analysis of the execution state of the web application, wherein the final attack string is generated so as to avoid filtering logic which is designed to filter a raw attack string including a predefined parameter. Therefore, the present invention can detect a security vulnerability, which cannot be detected by the existing dynamic analyzer, through easy generation of a final attack string capable of bypassing filtering.
Legal claims defining the scope of protection, as filed with the USPTO.
2. The operation method of claim 1, wherein the specific operation to be executed through the web application includes at least one of a distributed denial of service (DDoS) attack operation, a cross site scripting phishing (XSS) attack operation, an advanced persistent threat (APT) attack operation, a password cracking attack operation, a keylogging attack operation, a spoofing attack operation, and a rootkit attack operation.
4. The operation method of claim 3, wherein the specific operation to be executed through the web application includes at least one of a distributed denial of service (DDoS) attack operation, a cross site scripting phishing (XSS) attack operation, an advanced persistent threat (APT) attack operation, a password cracking attack operation, a keylogging attack operation, a spoofing attack operation, and a rootkit attack operation.
6. The server of claim 5, wherein the specific operation to be executed through the web application includes at least one of a distributed denial of service (DDoS) attack operation, a cross site scripting phishing (XSS) attack operation, an advanced persistent threat (APT) attack operation, a password cracking attack operation, a keylogging attack operation, a spoofing attack operation, and a rootkit attack operation.
Cooperative Patent Classification codes for this invention. Click any code to explore related patents in that topic.
July 28, 2016
November 8, 2022
Browse 5M+ US patents with plain-English claim translations and AI-generated analysis.